Hacker Read top | best | new | newcomments | leaders | about | bookmarklet login

> On WhatsApp there seems to be E2EE enabled but I have no idea what the keys are.

The keys are shown right in the contact's profile under "Encryption", same as Signal. It even has a feature to validate their key by taking a picture of their screen. How could it be any easier for laypeople than that?



view as:

WhatsApp website:

> This code can be found in the contact info screen, both as a QR code and a 60-digit number. These codes are unique to each chat and can be compared between people in each chat to verify that the messages you send to the chat are end-to-end encrypted. Security codes are just visible versions of the special key shared between you - and don't worry, it's not the actual key itself, that's always kept secret

So basically it's just a random unique number and could have no relationship to the key whatsoever. We'll never know.


It's easy to see it's calculated from the key since the validation will fail if the code is wrong.

What would it prove if they showed the private key in plain text?


Legal | privacy